]> wimlib.net Git - wimlib/blobdiff - src/verify.c
verify_swm_set(): Decrease scope of parts_to_swms
[wimlib] / src / verify.c
index 6602832a94a4fe05ce2061c44baff5ed4be936e7..777a6e0c7f06ff6f9165391e8d4d66985a0320ef 100644 (file)
@@ -35,14 +35,18 @@ static int verify_inode(struct wim_inode *inode, const WIMStruct *w)
        const struct wim_lookup_table *table = w->lookup_table;
        const struct wim_security_data *sd = wim_const_security_data(w);
        const struct wim_dentry *first_dentry = inode_first_dentry(inode);
+       const struct wim_dentry *dentry;
        int ret = WIMLIB_ERR_INVALID_DENTRY;
 
-       /* Check the security ID */
+       /* Check the security ID.  -1 is valid and means "no security
+        * descriptor".  Anything else has to be a valid index into the WIM
+        * image's security descriptors table. */
        if (inode->i_security_id < -1) {
                ERROR("Dentry `%s' has an invalid security ID (%d)",
                        first_dentry->full_path_utf8, inode->i_security_id);
                goto out;
        }
+
        if (inode->i_security_id >= sd->num_entries) {
                ERROR("Dentry `%s' has an invalid security ID (%d) "
                      "(there are only %u entries in the security table)",
@@ -51,9 +55,11 @@ static int verify_inode(struct wim_inode *inode, const WIMStruct *w)
                goto out;
        }
 
-       /* Check that lookup table entries for all the resources exist, except
-        * if the SHA1 message digest is all 0's, which indicates there is
-        * intentionally no resource there.  */
+       /* Check that lookup table entries for all the inode's stream exist,
+        * except if the SHA1 message digest is all 0's, which indicates an
+        * empty stream. 
+        *
+        * This check is skipped on split WIMs. */
        if (w->hdr.total_parts == 1) {
                for (unsigned i = 0; i <= inode->i_num_ads; i++) {
                        struct wim_lookup_table_entry *lte;
@@ -108,7 +114,7 @@ static int verify_inode(struct wim_inode *inode, const WIMStruct *w)
                }
        }
 
-       /* Make sure there is only one un-named stream. */
+       /* Make sure there is only one unnamed data stream. */
        unsigned num_unnamed_streams = 0;
        for (unsigned i = 0; i <= inode->i_num_ads; i++) {
                const u8 *hash;
@@ -121,6 +127,31 @@ static int verify_inode(struct wim_inode *inode, const WIMStruct *w)
                      first_dentry->full_path_utf8, num_unnamed_streams);
                goto out;
        }
+
+       /* Files cannot have multiple DOS names, even if they have multiple
+        * names in multiple directories (i.e. hard links).
+        * Source: NTFS-3g authors. */
+       const struct wim_dentry *dentry_with_dos_name = NULL;
+       inode_for_each_dentry(dentry, inode) {
+               if (dentry->short_name_len) {
+                       if (dentry_with_dos_name) {
+                               ERROR("Hard-linked file has a DOS name at "
+                                     "both `%s' and `%s'",
+                                     dentry_with_dos_name->full_path_utf8,
+                                     dentry->full_path_utf8);
+                               goto out;
+                       }
+                       dentry_with_dos_name = dentry;
+               }
+       }
+
+       /* Directories with multiple links have not been tested. XXX */
+       if (inode->i_nlink > 1 && inode->i_attributes & FILE_ATTRIBUTE_DIRECTORY) {
+               ERROR("Hard-linked directory `%s' is unsupported",
+                     first_dentry->full_path_utf8);
+               goto out;
+       }
+
        inode->i_verified = 1;
        ret = 0;
 out:
@@ -132,26 +163,33 @@ int verify_dentry(struct wim_dentry *dentry, void *wim)
 {
        int ret;
 
+       /* Verify the associated inode, but only one time no matter how many
+        * dentries it has. */
        if (!dentry->d_inode->i_verified) {
                ret = verify_inode(dentry->d_inode, wim);
                if (ret != 0)
                        return ret;
        }
 
-       /* Cannot have a short name but no long name */
-       if (dentry->short_name_len && !dentry->file_name_len) {
-               ERROR("Dentry `%s' has a short name but no long name",
-                     dentry->full_path_utf8);
-               return WIMLIB_ERR_INVALID_DENTRY;
-       }
-
-       /* Make sure root dentry is unnamed */
+       /* Make sure root dentry is unnamed, while every other dentry has at
+        * least a long name.
+        *
+        * I am assuming that dentries having only a DOS name is illegal; i.e.,
+        * Windows will always combine the Win32 name and DOS name for a file
+        * into a single WIM dentry, even if they are stored separately on NTFS.
+        * (This seems to be the case...) */
        if (dentry_is_root(dentry)) {
-               if (dentry->file_name_len) {
+               if (dentry->file_name_len || dentry->short_name_len) {
                        ERROR("The root dentry is named `%s', but it must "
                              "be unnamed", dentry->file_name_utf8);
                        return WIMLIB_ERR_INVALID_DENTRY;
                }
+       } else {
+               if (!dentry->file_name_len) {
+                       ERROR("Dentry `%s' has no long name",
+                             dentry->full_path_utf8);
+                       return WIMLIB_ERR_INVALID_DENTRY;
+               }
        }
 
 #if 0
@@ -174,11 +212,13 @@ static int image_run_full_verifications(WIMStruct *w)
 static int lte_fix_refcnt(struct wim_lookup_table_entry *lte, void *ctr)
 {
        if (lte->refcnt != lte->real_refcnt) {
+       #ifdef ENABLE_ERROR_MESSAGES
                WARNING("The following lookup table entry has a reference "
                        "count of %u, but", lte->refcnt);
                WARNING("We found %u references to it",
                        lte->real_refcnt);
-               print_lookup_table_entry(lte);
+               print_lookup_table_entry(lte, stderr);
+       #endif
                lte->refcnt = lte->real_refcnt;
                ++*(unsigned long *)ctr;
        }
@@ -274,48 +314,54 @@ int verify_swm_set(WIMStruct *w, WIMStruct **additional_swms,
        ctype = wimlib_get_compression_type(w);
        guid = w->hdr.guid;
 
-       WIMStruct *parts_to_swms[num_additional_swms];
-       ZERO_ARRAY(parts_to_swms);
-       for (unsigned i = 0; i < num_additional_swms; i++) {
+       {
+               /* parts_to_swms is not allocated at function scope because it
+                * should only be allocated after num_additional_swms was
+                * checked to be the same as w->hdr.total_parts.  Otherwise, it
+                * could be unexpectedly high and cause a stack overflow. */
+               WIMStruct *parts_to_swms[num_additional_swms];
+               ZERO_ARRAY(parts_to_swms);
+               for (unsigned i = 0; i < num_additional_swms; i++) {
 
-               WIMStruct *swm = additional_swms[i];
+                       WIMStruct *swm = additional_swms[i];
 
-               if (wimlib_get_compression_type(swm) != ctype) {
-                       ERROR("The split WIMs do not all have the same "
-                             "compression type");
-                       return WIMLIB_ERR_SPLIT_INVALID;
-               }
-               if (memcmp(guid, swm->hdr.guid, WIM_GID_LEN) != 0) {
-                       ERROR("The split WIMs do not all have the same "
-                             "GUID");
-                       return WIMLIB_ERR_SPLIT_INVALID;
-               }
-               if (swm->hdr.part_number == 1) {
-                       ERROR("WIMs `%s' and `%s' both are marked as the "
-                             "first WIM in the spanned set",
-                             w->filename, swm->filename);
-                       return WIMLIB_ERR_SPLIT_INVALID;
-               }
-               if (swm->hdr.part_number == 0 ||
-                   swm->hdr.part_number > total_parts)
-               {
-                       ERROR("WIM `%s' says it is part %u in the spanned set, "
-                             "but the part number must be in the range "
-                             "[1, %u]",
-                             swm->filename, swm->hdr.part_number, total_parts);
-                       return WIMLIB_ERR_SPLIT_INVALID;
-               }
-               if (parts_to_swms[swm->hdr.part_number - 2])
-               {
-                       ERROR("`%s' and `%s' are both marked as part %u of %u "
-                             "in the spanned set",
-                             parts_to_swms[swm->hdr.part_number - 2]->filename,
-                             swm->filename,
-                             swm->hdr.part_number,
-                             total_parts);
-                       return WIMLIB_ERR_SPLIT_INVALID;
-               } else {
-                       parts_to_swms[swm->hdr.part_number - 2] = swm;
+                       if (wimlib_get_compression_type(swm) != ctype) {
+                               ERROR("The split WIMs do not all have the same "
+                                     "compression type");
+                               return WIMLIB_ERR_SPLIT_INVALID;
+                       }
+                       if (memcmp(guid, swm->hdr.guid, WIM_GID_LEN) != 0) {
+                               ERROR("The split WIMs do not all have the same "
+                                     "GUID");
+                               return WIMLIB_ERR_SPLIT_INVALID;
+                       }
+                       if (swm->hdr.part_number == 1) {
+                               ERROR("WIMs `%s' and `%s' both are marked as the "
+                                     "first WIM in the spanned set",
+                                     w->filename, swm->filename);
+                               return WIMLIB_ERR_SPLIT_INVALID;
+                       }
+                       if (swm->hdr.part_number == 0 ||
+                           swm->hdr.part_number > total_parts)
+                       {
+                               ERROR("WIM `%s' says it is part %u in the spanned set, "
+                                     "but the part number must be in the range "
+                                     "[1, %u]",
+                                     swm->filename, swm->hdr.part_number, total_parts);
+                               return WIMLIB_ERR_SPLIT_INVALID;
+                       }
+                       if (parts_to_swms[swm->hdr.part_number - 2])
+                       {
+                               ERROR("`%s' and `%s' are both marked as part %u of %u "
+                                     "in the spanned set",
+                                     parts_to_swms[swm->hdr.part_number - 2]->filename,
+                                     swm->filename,
+                                     swm->hdr.part_number,
+                                     total_parts);
+                               return WIMLIB_ERR_SPLIT_INVALID;
+                       } else {
+                               parts_to_swms[swm->hdr.part_number - 2] = swm;
+                       }
                }
        }
        return 0;